Categories
Corporate Law Data Protection Governance High Court Legal Alerts

Data Protection Brief Case – August & September 2026

Data Protection Brief Case – August & September 2026

We are pleased to present the August-September 2026 edition of our Data Protection & Privacy Newsletter, covering key developments in India’s data protection, privacy and cyber reporting landscape, along with notable developments from the EU, UK, US and Singapore. The phased rollout of India’s Digital Personal Data Protection framework remains a key focus this month, with the Government reiterating the implementation timeline under the DPDP Rules, 2025, alongside developments in sectoral incident reporting and the continuing debate before the Delhi High Court on privacy and public access to judicial records. Beyond India, we examine significant privacy enforcement developments, including the European regulatory actions concerning location data and automated decision making, developments concerning children’s privacy in the UK and US, and Singapore’s guidance on the use of personal data in generative AI. We also look at the evolving AI regulatory landscape, including the EU AI Act entering an enforcement phase, the RBI’s approach to responsible AI adoption in the banking sector, and the Delhi High Court’s recent decision in ANI v. OpenAI. So, sit back, enjoy your favourite beverage, and explore the latest developments shaping the data protection, privacy and AI regulatory landscape.

The law develops

Government restates the DPDP rollout timetable

In a Lok Sabha answer on 12 August 2026, MeitY reiterated that the DPDP Rules, 2025 were notified on 13 November 2025 and explained the three stage rollout over the 18 month transition period. The first stage covers the establishment and functioning of the Data Protection Board, followed by the registration and functioning of consent managers within one year. The remaining provisions, including obligations relating to data principal rights, security safeguards and breach notification, are to take effect within 18 months. For organisations, this transition period provides an opportunity to identify the personal data they handle, review their privacy notices and consent processes, and test their procedures for responding to data breaches.

Read: Lok Sabha Unstarred Question 3943, answered 12 Aug  |  MeitY rules page

State of play

SEBI moves incident reporting to a structured portal

SEBI’s 24 August 2026 circular aligns its Cyber Incident Reporting Portal with the Financial Stability Board’s FIRE format. Reporting can now track an incident from first report through updates to closure. The circular directs regulated entities to use the portal and to read it with SEBI’s existing cybersecurity framework. Firms should check their incident playbooks for the portal workflow and keep the underlying reporting deadlines in view.

Read: SEBI circular HO/(449)2026-ITD-5_DIV1/I/19448/2026 (24 Aug)

Government departments are asked to prepare

A 27 August 2026 report says the Cabinet Secretary directed central ministries, states and union territories to prepare time-bound plans for DPDP compliance, including data inventories, consent and grievance arrangements, governance and technical safeguards. This is a reported administrative push, not a newly notified duty for private companies. The same inventory and ownership questions are worth asking across sectors.

Read: Times of India (27 Aug)

From the docket

Court records and the right to be forgotten

Indian Kanoon has appealed a single judge’s judgment of 29 May 2026, which recognised a right to be forgotten and directed search engines and legal databases to de-index and disable name-based searches for the records in issue. In September hearings on those appeals, a Delhi High Court division bench questioned broad restrictions on name-based searches of judicial records. On 9 September 2026 it asked whether a more individual assessment could protect privacy without blanket masking; on 16 September it pressed the access-to-law implications for lawyers using a free database. These are observations in pending appeals, not a final ruling on a general right to de-index court records. The case is a useful reminder that privacy claims need to be weighed against the public character and practical accessibility of judgments.

Read: LiveLaw (9 Sep)  |  MediaNama (17 Sep)

Beyond India

EU: location data, lawful use and fines

On 21 September 2026, Ireland’s Data Protection Commission imposed €403 million in fines on Google Ireland over the processing of location data in three features between May 2018 and February 2020, and ordered compliance within six months. Its findings addressed lawfulness and fairness, transparency, accountability and retention. The same week the European Data Protection Board (EDPB) adopted a five-step approach to deciding whether to impose an administrative fine. That new fining guidance is open for public consultation until 13 November; it is not itself an amendment to the General Data Protection Regulation (GDPR).

Read: EDPB, Google decision (21 Sep) | EDPB, fining guidance (21 Sep)

EU: Uber fined for automated driver deactivations

On 21 August 2026, the Dutch Data Protection Authority fined Uber €825 million for using fully automated systems to deactivate driver accounts, between 2018 and 2022, without adequate human review or sufficient information to the drivers affected. The finding rests on the GDPR’s restriction on solely automated decisions with significant effects on individuals. Uber has disputed the finding and said it will appeal. It is the second-largest GDPR fine to date, behind Meta’s 2023 penalty, and lands the month before the Google decision above: two large European fines within weeks of each other, one on transparency and retention, the other on automated decision-making.

Read: Dutch DPA, Uber decision (21 Aug)

UK: children’s data and recommender systems

On 24 September, the  Information Commissioner’s Office (ICO) of United Kingdom said TikTok had withdrawn its appeals and accepted the £12.7 million fine imposed in 2023 for children’s data breaches. It also withdrew an appeal against an information notice in a separate, ongoing investigation into the use of 13- to 17-year-olds’ data in recommender systems. The fine is final but the separate investigation is not. The ICO’s August facial-recognition audits of police forces similarly put lawful basis, accuracy, bias and governance ahead of a simple “AI yes or no” question.

Read: ICO, TikTok (24 Sep) | ICO, facial recognition (18 Aug)

US: data-driven pricing under scrutiny

The Federal Trade Commission sought comment on 19 August 2026, on a proposed enforcement policy statement about personalised pricing based on consumers’ personal data. The proposal warns that undisclosed collection or use of such data to set prices may be unfair or deceptive under the Federal Trade Commission (FTC) Act. It is a consultation, not a new nationwide privacy statute or a final enforcement rule. For businesses using profiling, the issue is whether the person knows which data are being used to decide what price they see.

Read: FTC consultation (19 Aug; updated 31 Aug)

US: TikTok settles federal children’s-privacy claims

On 21 August 2026, the US Department of Justice announced a USD 400 million settlement with TikTok and ByteDance in connection with a 2024 lawsuit alleging violations of the Children’s Online Privacy Protection Act (COPPA). TikTok will pay USD 300 million immediately, with a further USD 100 million payable once a related 2019 consent decree involving its predecessor Musical.ly is vacated. The Department of Justice described the settlement as one of the largest COPPA recoveries on record, while TikTok did not admit liability. The development is another indication that children’s privacy remains a significant area of regulatory scrutiny, particularly for online platforms that collect and use children’s data.

Read: DOJ press release (21 Aug)

Singapore: guidance for generative AI data

On 20 July 2026, Singapore’s Personal Data Protection Commission (PDPC) published advisory guidelines on the use of personal data in generative AI. They address collection and use for model development, the allocation of responsibilities across the lifecycle, and requests from individuals. This is guidance on the existing PDPA framework, not a new AI statute. It offers a useful comparator for Indian teams assessing data provenance and responsibility between a model provider and deployer.

Read: PDPC advisory guidelines (20 Jul; context)

AI: what regulators and courts are asking

EU rules enter an enforcement phase

From 2 August 2026, the European Commission’s AI Office and national authorities began enforcing applicable AI Act rules. New transparency duties cover disclosures when people interact with certain AI systems and labelling of deepfakes and certain AI-generated or altered content. The AI Act is risk-based; these transparency duties should not be confused with every high-risk-system requirement, whose timetable was deferred by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July) to 2 December 2027 for stand-alone systems and 2 August 2028 for AI embedded in regulated products. The practical question for privacy teams is how AI disclosures sit alongside notice, lawful basis and rights under the GDPR.

Read: European Commission (31 Jul; effective 2 Aug)

India: prudence before scale

India’s AI discussion remains a mix of guidance and sector-specific oversight rather than one generally applicable AI Act. In an address on 19 August 2026, an RBI Deputy Governor called for responsible adoption in banking, with human judgment and accountability alongside models. A second RBI address on 24 September said governance must precede scale, and warned that AI can amplify errors as readily as efficiency. These are regulatory speeches, not binding circulars. The DPDP rollout described above remains the relevant horizontal personal-data track when AI uses personal data.

Read: RBI address (19 Aug) | RBI address (24 Sep)

Courts: ANI v OpenAI and the limits of interim relief

On 24 July 2026, the Delhi High Court dismissed ANI Media’s interim-injunction application against OpenAI. ANI alleged that OpenAI copied its news works for model training and reproduced protected expression in ChatGPT responses. US-based training servers did not, prima facie, oust jurisdiction: training and output were linked, and OpenAI served users in Delhi.

The judge took a prima facie view that storing ANI’s original literary works for training was fair dealing under section 52(1)(a) of the Copyright Act (‘private or personal use, including research’). The inquiry weighed use limited to training, market harm and public interest. ANI had not shown memorisation or regurgitation, or substantial similarity in the outputs examined. This is no blanket permission to scrape or reproduce news.

ANI could block crawlers; OpenAI said it had blocked ANI’s site. ANI showed no lost subscribers and had offered a paid licence. The court found damages could compensate ANI if it won, while an injunction risked harm to OpenAI and the public. The final merits remain open; no deletion or licence was ordered.

The broad outcome: Developers should document sources, access controls and output testing; publishers should preserve examples of copying and market harm. Copyright fair dealing is separate from privacy compliance. The order did not decide DPDP obligations or authorise use of personal data.

Read: Delhi High Court, ANI Media v OpenAI, interim order (24 Jul 2026)

We will be back next month with another update. Thank you for reading! 

DISCLAIMER 

The content provided in this newsletter is intended for general awareness and should not be considered as legal advice. Readers are advised to consult with a qualified legal professional regarding any specific issues mentioned herein. If you have any questions about any of these developments or would like to see something different next month, reach out to us at data@sarthaklaw.com .